Jump to content

Recommended Posts

Posted (edited)

Hey Everyone!

 

Just wondering if anyone has implemented RADIUS based VLANs on their organisation/school, be very interested in how you did it!

 

cheers

 

Tom (wow it turned out I cannot spell Radius- sorry all!)

Edited by Speedydowt
Posted

Yup, been running them for 5+ years here. We have IAS set up with a bunch of rules, the core switch (HP 5406zl) talks with that, and all the ports across the network are set to use aaa port-based mac address auth. Then, in our AD we have a username for each MAC address that's allowed on, and groups which match up with the IAS rules for each vlan.

 

Some devices do not like this though (printers mostly) and have their vlan st statically on the switches.

 

I'm pondering moving as much as I can over to 802.1x based auth though, using login names etc... We've started the move for Wi-Fi already.

Posted

It works ok, the details are set by GPO for our windows 7 laptops. We're using a single vlan with multiple ssids at the moment but later this summer we're moving to 3 vlans. One which will be dedicated to 802.1x.

 

The other 2 will be for guests and for non-802.1x devices but authenticated by the proxy.

Posted

No idea what is there now, but for a number of years (with XP, Vista, 7, os x, printers) I ran an entirely RADIUS vlan assigned network, wired and wireless. I combined this with the 5400 ACLs to have different server vlans available to different clients.

 

All procurve with 802.1x for domain machine vlan assignment, MAC auth for printers and devices that don't support 802.1x and Apple machines (although now they have better 802.1x iirc). It worked pretty well, non auth machines ended up in an unauthenticated VLAN that only had WDS/mac imaging and domain join facilities. Gets around multicast on vlans with WDS as they all drop into the unauthenticated when network booting!

 

Still some issues with windows 7 not holding netlogon for the auth, but it works nearly all the time.

 

Only ever defeated by a phone system that had to have static vlan assignment, it was very quiet, never sent any traffic out when you plugged it into the network - no MAC gets seen for the switch to authenticate!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...